Menu
Cyberspy group targets South American political figures, journalists

Cyberspy group targets South American political figures, journalists

The groups's activity has spanned seven years, affecting influential people in Argentina, Ecuador, Venezuela and possibly Brazil

Since 2008, a group of attackers has used off-the-shelf remote access Trojans (RATs) to target political figures, journalists and public figures in several South American countries. 

The group, whose attack campaigns have been investigated by researchers working with Citizen Lab at the University of Toronto's Munk School of Global Affairs, has been dubbed Packrat. It appears mainly interested in political opposition groups and influential people from countries like Argentina, Ecuador and Venezuela.

While there is insufficient evidence to link the group to a particular government or intelligence agency, the researchers believe "that the ultimate recipient of the information collected by Packrat is likely one or more governments in the region."

The group commonly uses politically themed phishing emails to distribute commercial RATs to their intended targets, which have included high-profile Argentine prosecutor Alberto Nisman, investigative journalist and television host Jorge Lanata and reportedly Maximo Kirchner, the son of former Argentine presidents Néstor Kirchner and Cristina Fernández de Kirchner.

There is evidence from file compilation dates and command-and-control infrastructure to suggest that between 2008 and 2013 the group targeted individuals from Brazil. However, the Citizen Lab researchers couldn't identify or confirm any victims from that period.

By 2014, the group had moved to targeting influential people from Argentina and also started campaigns against targets from Ecuador and Venezuela. The researchers found evidence of malware attacks this year against public figures from Ecuador.

In addition to infecting computers with malware, the group also created fake online political opposition movements and organizations that were likely used for disinformation in Ecuador and Venezuela.

Over the years, the group has used several RATs in their attacks, including CyberGate, XTreme RAT, AlienSpy and Adzok. The Citizen Lab researchers connected the attacks to a single group after finding strong correlations between their command-and-control infrastructures.

While the malware used in one of the attacks was being analyzed, one of the attackers started leaving taunting and threatening messages in Spanish on the test system used by researchers. These messages included: "We are going to analyze your brain with a bullet and your family too;" "You like playing the spy where you shouldn’t, you know it has a cost, your life;" "We have your picture;" and "Take care of your family."

"Packrat highlights the extent to which multi-year campaigns can be run using limited technical sophistication, and a lot of creativity," the researchers said in their analysis report. "From a technical perspective, they rely almost entirely on off-the-shelf RATs and packers to evade antivirus detection. Where they excel is in the time and effort spent to create detailed and moderately convincing fake organizations to seed their malware."


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Featured

Slideshows

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners

This year’s Reseller News 30 Under 30 Tech Awards were held as an integral part of the first entirely virtual Emerging Leaders​ forum, an annual event dedicated to identifying, educating and showcasing the New Zealand technology market’s rising stars. The 30 Under 30 Tech Awards 2020 recognised the outstanding achievements and business excellence of 30 talented individuals​, across both young leaders and those just starting out. In this slideshow, Reseller News honours this year's winners and captures their thoughts about how their ideas of leadership have changed over time.​

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners
Reseller News Exchange Auckland: Beyond the myths — how partners can master cloud security

Reseller News Exchange Auckland: Beyond the myths — how partners can master cloud security

This exclusive Reseller News Exchange event in Auckland explored the challenges facing the partner community on the cloud security frontier, as well as market trends, customer priorities and how the channel can capitalise on the opportunities available. In association with Arrow, Bitdefender, Exclusive Networks, Fortinet and Palo Alto Networks. Photos by Gino Demeer.

Reseller News Exchange Auckland: Beyond the myths — how partners can master cloud security
Reseller News welcomes industry figures at 2020 Hall of Fame lunch

Reseller News welcomes industry figures at 2020 Hall of Fame lunch

Reseller News welcomed 2019 inductees - Leanne Buer, Ross Jenkins and Terry Dunn - to the fourth running of the Reseller News Hall of Fame lunch, held at the French Cafe in Auckland. The inductees discussed the changing face of the IT channel ecosystem in New Zealand and what it means to be a Reseller News Hall of Fame inductee. Photos by Gino Demeer.

Reseller News welcomes industry figures at 2020 Hall of Fame lunch
Show Comments